All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-configobj | Aug 9, 2023 | Apr 3, 2023 |
| Debian | — | No solution existsUpgrade configobj | May 15, 2025 | Apr 3, 2023 |
| Freebsd | — | Upgrade py39-configobjUpgrade py311-configobjUpgrade py310-configobjUpgrade py38-configobj | Apr 14, 2023 | Apr 9, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python3-configobj | Jan 10, 2024 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade python3-configobj | Feb 11, 2025 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp12 | — | Upgrade python3-configobj | Feb 11, 2025 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-configobj | Feb 12, 2024 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python2-configobjUpgrade python3-configobj | Mar 13, 2024 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-configobj | Apr 9, 2024 | Apr 3, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 3, 2023 |
| Suse | — | Upgrade python-configobjUpgrade python3-configobj | Aug 23, 2023 | Apr 3, 2023 |
| Ubuntu | — | Upgrade python3-configobjUpgrade python3-configobj (Ubuntu Pro)Upgrade python-configobj (Ubuntu Pro) | Sep 27, 2024 | Apr 3, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub